Online tracking is the practice of following a device or an account across websites, apps and services, usually to build a profile for advertising or to measure behaviour. This is a beginner-level guide to how it works and how to reduce it. It is written for people protecting their own privacy, and for the professionals who advise them. Nothing here is about following another person, monitoring a partner or employee, or building a dossier on someone without their consent, which in many places is unlawful regardless of the technology used.
The first thing to understand is that tracking is rarely one system but a stack of small overlapping ones. Blocking one does not stop the rest, which is why an ad blocker alone leaves much behind. The nine methods below cover almost everything you will encounter, and each has a control that reduces it.
What Online Tracking Is and Why It Works So Well
Tracking works because the web is stateless by default. When you open a page the site learns an address, a user agent, a screen size, a language and a timestamp, then forgets you. Something must be sent back to make the connection persistent, and everything else varies that.
Three properties make it effective. It is cheap, since a request to an advertising server costs almost nothing. It is invisible, since nothing appears on screen. And it is cumulative, because each record is worth more joined to another. The MDN overview of privacy on the web sets out the platform behaviour, and the Information Commissioner’s Office guidance on tracking covers the regulatory view, including the need for a genuine choice where consent is relied on.
A cookie is a small piece of text a site asks your browser to store and send back later. The behaviour is specified in RFC 6265, the HTTP state management mechanism, and the attributes controlling them, including expiry and same-site, are in the MDN reference for the Set-Cookie header.
A first-party cookie is set by the site you are visiting. It is usually benign and often necessary: it keeps you signed in or remembers your basket. Deleting it is rarely harmful and frequently annoying. First-party cookies are not the main privacy problem, and a good blocking rule tells them apart.
A third-party cookie is set by a domain other than the one in your address bar, usually an advertising or analytics provider embedded in the page. Because that domain appears on thousands of unrelated sites, one value links your visits into a single profile. This is the mechanism that made cross-site tracking routine, and the reason browsers have restricted it in recent years.
That is a genuine improvement but not a full answer. It applies only where the browser enforces it, it does not help with a site you log into directly, and it leaves methods needing no stored identifier untouched. The WebKit account of its tracking prevention work describes measurement that keeps the count but drops the cross-site identifier.
Pixels, Beacons and Other Invisible Requests
A tracking pixel is a one-pixel image, a transparent one, or an empty request embedded in an email or a page. Loading the resource tells the sender that this person, on this device, at this moment, opened this message. Marketing email is where most people meet it first, and the clearest example of tracking tied to one individual rather than a cohort.
The same pattern appears in share buttons, embedded videos, chat widgets and social scripts. Each is small; together they mean a surprising number of third-party domains on one ordinary page. The practical defence is content blocking plus permissions that deny by default, so unknown domains are not contacted unless you approve them. Our guide to social media security covers the trade-off, since the same blocking reduces functionality.
Browser Fingerprinting: Tracking Without Storing Anything
Fingerprinting observes the small incidental differences between your setup and everyone else’s, then treats that combination as an identifier. No cookie is set and nothing is written to disk, so clearing history and cookies changes nothing: the signal is recomputed on every visit. That makes it the hardest of the nine to remove, and the reason it has become the default fallback.
How fingerprinting is built from ordinary signals
The inputs are innocuous details that together narrow things down. Canvas fingerprinting renders an off-screen image and hashes the result, which varies with your graphics drivers, fonts and rendering settings; audio fingerprinting does the same with a generated sound, which varies with your audio stack. Alongside those come screen dimensions, colour depth, time zone, language list, installed fonts, hardware concurrency and the order of browser features you support. A modest number of these yields a signature that is stable across sessions and largely unique across people, so it substitutes for a blocked cookie.
The industry’s answer is fingerprint resistance: reducing these signals to a small set of common values so your device looks typical rather than itself. WebKit’s work on reducing fingerprinting surface is the most detailed public account. It is a technical mitigation rather than a policy promise, it remains partial, and it depends on the browser you choose.
Data Brokers, Session Replay and Mobile SDKs
Browser and email methods cover only part of the picture, and the remaining channels are what a browser setting cannot reach.
Data brokers and people-search sites
Data brokers assemble profiles from public records, bulk purchases, loyalty cards and partner sources, then resell access to anyone who asks. People-search services do a narrower version and usually let you remove a listing, which is the first place to check. This is tracking at its most literal: not behaviour on a website, but a commercial file about your life. The Office of the Privacy Commissioner of Canada explains how this model works. It is the channel most likely to survive every browser change.
Session replay, analytics and mobile SDKs
Session replay tools record what a user does on a page so teams can watch where people get stuck. SDKs embedded in mobile apps report screen views and events from devices where browser protections do not apply, and an app can request an advertising identifier unique to the app rather than to you. A poorly configured SDK can capture typed text, turning a usability tool into a record of sensitive input. Reviewing the permissions your apps request is one of the highest-value privacy actions available to an individual.
What Actually Reduces Online Tracking
| Method | What it identifies | Where it lives | What reduces it |
|---|---|---|---|
| First-party cookies | Your session on one site | Browser storage | Clear on a schedule, restrict third-party cookie access |
| Third-party cookies | One identity across many sites | Browser storage, shared domain | Browser-level restriction, blocking rules |
| Tracking pixels and beacons | That you opened a message or page | Email client or page request | Image and request blocking, server-side previews |
| Browser fingerprinting | The device, with nothing stored | Recomputed on every visit | Browser with fingerprint resistance, reduced feature exposure |
| Device identifiers | The app or install | App storage, platform settings | Reset the identifier, limit app permissions |
| Cross-site tracking | Your activity stitched together | Server-side joining of identifiers | Third-party cookie limits, limited login sharing, fewer shared scripts |
| Data brokers | You, assembled from records | Commercial databases | Opt out, request removal, limit what you publish |
| Session replay | Every action on a page | Vendor recordings | Do not enter sensitive data, or mask inputs |
| Analytics and app SDKs | Screen views and events | Vendor servers, device | Revoke permissions, use fewer apps, network filtering |
Ranked by effect, the steps that work are unglamorous. Choose a browser that restricts third-party cookies and resists fingerprinting, and keep it updated. Install a content blocker covering trackers as well as ads. Clear cookies periodically, which removes the accumulation of identifiers rather than your history. Allow fewer extensions and embedded scripts, since each is another party on the page. Review app permissions on your phone and reset the advertising identifier where offered. Finally, treat search and social accounts carefully: logging in to read an article hands that site a verified identifier, and linking accounts to single sign-on multiplies the value of everything collected. For the connected-device side, see our guide to security for smart devices; public Wi-Fi security covers the network side.
Frequently Asked Questions
How do I check what is tracking me?
Your browser’s developer tools contain a storage panel showing cookies and site data for the current page, and most blockers log what they blocked on each site. Both give a realistic picture of the trackers on one page, more useful than any global figure.
Does private browsing stop online tracking?
It reduces it. Private windows keep no cookies, local storage or history between sessions, so last week’s identifier is gone. They do not stop fingerprinting, server-side logging of your IP address, or broker records, because those need nothing in your browser.
Is an ad blocker enough?
No. An ad blocker removes a large share of third-party requests but rarely removes fingerprinting, broker records, session replay or app tracking. Treat it as one layer.
What is fingerprint resistance?
It is a browser technique that limits how distinctive your device appears, standardising the values a site can read so most devices look similar. It reduces fingerprint-based tracking without asking the user to manage anything, so browser choice matters more here than any extension.
Can I remove myself from data brokers?
Usually, yes, and worth doing, though expect repetition. Each broker has its own opt-out, removal can take weeks, and new records appear later, so treat it as maintenance. Limiting what you publish publicly reduces how much there is to buy.
Key Takeaways
- Tracking in practice is a stack of overlapping systems, so removing one does little on its own.
- Third-party cookies made cross-site tracking routine; browser restrictions now reduce it.
- Pixels and beacons tie a visit to a specific person, most obviously in marketing email.
- Fingerprinting stores nothing, so clearing cookies and history does not defeat it.
- Data brokers, session replay and app SDKs operate outside anything a browser setting can reach.
- Browser choice and content blocking together cover more than either does alone.
- App permissions and broker opt-outs stay worth the effort after every browser update.
For the regulatory side, the ICO guidance linked above is the clearest starting point for organisations. For what happens to data once collected, read email security and phishing, which covers the other channel most often used to reach you directly.
Sources: RFC 6265, HTTP State Management Mechanism, RFC Editor; MDN Web Docs, Set-Cookie header; MDN Web Docs, Privacy on the web; Information Commissioner’s Office, online tracking; Office of the Privacy Commissioner of Canada, online privacy, tracking and cookies; WebKit, WebKit Features in Safari 16.4.
0 Comments